eSecurity Planet
Researchers uncovered more than 119,000 DoppelCart fake shopping domains impersonating thousands of brands and collecting shoppers’ payment information. The post 119,000 Fake Shops Are Mimicking Real Brands to Steal Card Details appeared first on eSecurity Planet .
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords. The post AI-Orchestrated PaperCut Attack Compromises 440 Servers Across 48 Countries appeared first on eSecurity Planet .
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords. The post Hackers Are Hijacking Claude Accounts and Burning Through Paid Usage appeared first on eSecurity Planet .
A seller is offering 32.8 million alleged Condé Nast user records for $15,000, potentially exposing subscriber details useful for targeted phishing. The post 32.8 Million Alleged Condé Nast Records Offered for $15,000 appeared first on eSecurity Planet .
AI and human risk are reshaping CISO priorities as board expectations grow. The post AI and Human Risk Reshape CISO Priorities in 2026 appeared first on eSecurity Planet .
US agencies say six China-based AI firms used large-scale distillation campaigns to extract capabilities from Claude, GPT, Gemini, and Grok models. The post NSA, FBI, CISA Warn of Industrial-Scale AI Model Distillation Attacks appeared first on eSecurity Planet .
Passwd is a Google Workspace-focused password manager with strong usability, flexible pricing, passkey support, and private cloud deployment options. The post Passwd Review 2026: A Top Password Manager for Google Workspace appeared first on eSecurity Planet .
Check Point researchers found a ChatGPT flaw that let attackers run hidden tasks and retrieve connected Gmail data through a cross-account channel. The post ChatGPT Flaw Let Attackers Secretly Hijack a Victim’s AI Session appeared first on eSecurity Planet .
KnowBe4 found hackers abusing trusted Google services to hide phishing pages that steal Microsoft credentials and enable persistent ScreenConnect remote access. The post Hackers Route Phishing Through Google to Steal Microsoft Credentials appeared first on eSecurity Planet .
Google warns that hackers are using AI agents to automate attack stages, harvest credentials, and accelerate cyberattacks with less human direction. The post Google Warns Hackers Are Turning AI Agents Into Attack Tools appeared first on eSecurity Planet .
Microsoft’s September 2026 Patch Tuesday fixes nearly 1,000 vulnerabilities, including two Windows zero-days already exploited in attacks. The post Microsoft’s September Patch Tuesday Fixes Nearly 1,000 Flaws, Including 2 Exploited Zero-Days appeared first on eSecurity Planet .
Researchers found 220.8 million passenger and crew records exposed through default credentials in a Vietnam-linked database containing sensitive travel data. The post 220 Million Travel Records Exposed Through Default Credentials appeared first on eSecurity Planet .
Adobe patched the actively exploited CVE-2026-75650 Magento zero-day, but compromised stores still need malware hunting and broad credential rotation. The post CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn’t Enough appeared first on eSecurity Planet .
Google says China-linked hackers are running AI inside compromised cloud environments, using victims’ computing power while reducing outside monitoring. The post Google Finds Chinese Hackers Running AI on Compromised Networks appeared first on eSecurity Planet .
The G7 says organizations should start post-quantum migration now by inventorying cryptographic dependencies and prioritizing high-risk systems. The post G7 Urges Organizations to Start Post-Quantum Migration Now appeared first on eSecurity Planet .
Researchers used AI to build WeWorm, a zero-click WeChat exploit that could hijack accounts through unanswered calls before Tencent mitigated the flaw. The post AI-Assisted WeChat Worm Put 1 Billion Accounts at Potential Risk appeared first on eSecurity Planet .
PEEP malware turns compromised Chrome and Edge browsers into persistent backdoors for credential theft, session hijacking, and host command execution. The post PEEP Turns Chrome, Edge Into Post-Compromise Backdoors appeared first on eSecurity Planet .
Samsung’s September 2026 security update lists fixes tied to 90 vulnerabilities, including critical Android and Galaxy flaws. The post Samsung’s September Update: Fixes for 90 Security Vulnerabilities on Galaxy Devices appeared first on eSecurity Planet .
BigBear 2.0 bypassed Microsoft 365 MFA at 258 organizations by stealing session cookies. Learn how the phishing service works and how to respond. The post BigBear 2.0 Bypasses Microsoft 365 MFA at 258 Organizations appeared first on eSecurity Planet .

research.ioSign up to keep scrolling
Create your feed subscriptions, save articles, keep scrolling.